Cannot establish connection to ZTNA service when going through a Proxy
search cancel

Cannot establish connection to ZTNA service when going through a Proxy

book

Article ID: 387401

calendar_today

Updated On:

Products

Symantec ZTNA

Issue/Introduction

ZTNA connector installed successfully on Docker host.

Docker host setup to send all traffic through an Web proxy (usually on-premise).

When trying to run the docker container the docker instance fails to start and returns connectivity related errors e.g.  net/http: "request canceled while waiting for connection" or "connection aborted"

Proxy has protocol detection enabled and handles both SSL and HTTPS traffic.

 

Environment

Docker container accessing ZTNA service via Web Proxy.

Web proxy setup with SSL interception by default.

Cause

Proxy rejecting protocols that are not recognised.

Resolution

Make sure that protocol detection is DISABLED on the proxy handling the ZTNA docker connection into the ZTNA service.

The ZTNA IP addresses to bypass protocol detection for both EMEA and US are documented in the "IP address requirements" section here.